Details
-
Page
-
Resolution: Fixed
-
Major
-
None
-
None
-
47: Documentation 2
-
1
Description
When doing any form of intra-Kubernetes networking you need to be careful. If the VIP address range aliases with remote pods, you get black holes. If the VIP address range aliases with remote nodes when using an SNAT based approach, you get black holes.
Also worth mentioning that NAT is best avoided due to statefullness, finite conntrack table size and the magic of dropped connections.